SA-CONTRIB-2026-214: Critical severity drupal/permissions_by_term vulnerability

Published Oct 7, 2026
·
Updated

This module enables you to restrict view access to single nodes via taxonomy terms. The module doesn't sufficiently check access rights when in "Permission mode" and a node referencing a deleted taxonomy term is accessed via JSON:API. This vulnerability is mitigated by the fact that it requires a specific module configuration, references to a deleted term, and access via JSON:API to be present.

Credit

ayrmax

Affected Software

1 affected componentFixes available
drupal/permissions_by_term<3.1.41
3.1.41

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade drupal/permissions_by_term to a version that resolves this vulnerability.

    Fixed in 3.1.41

Event History

Oct 7, 2026
Advisory Published
via Drupal·12:00 AM
Data Sourced
via Drupal·12:00 AM
DescriptionSeverityAffected Software

Child vulnerabilities

Contains the following vulnerabilities.

Frequently Asked Questions

1

Which deployments are exposed?

Exposure requires the module to be configured in Permission mode, nodes that still reference deleted taxonomy terms, and JSON:API access. Deployments missing any of these conditions are mitigated according to the advisory.

2

What does an attacker need to exploit this issue?

An attacker must access an affected node through JSON:API. The affected node must reference a deleted taxonomy term while the module is operating in Permission mode.

3

How can I assess whether my site may be affected?

Review the module configuration to determine whether Permission mode is enabled. Then identify nodes with references to deleted taxonomy terms and confirm whether those nodes are accessible through JSON:API.

4

What can be done if patching is not immediately possible?

Reduce exposure by avoiding Permission mode, remediating node references to deleted taxonomy terms, or restricting JSON:API access. These steps address the conditions identified as necessary for exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203